Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Sandbox-side proposal audit (CONFIG:PROPOSED and /wait decisions) names only the first endpoint

Aperta Adatta ai principianti
#4,240 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@ericcurtin ci sta già lavorando.

Dal 7/10/2026.

  • #4313 di @ericcurtin — aperta

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
78/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
rust
Ambito
security

Direzione di ricerca

Inizia in openshell-supervisor-network/src/policy_local.rs alla funzione summarize_chunk_for_audit (intorno alla riga 695), poi trova i suoi test esistenti. Traccia come la funzione riassume gli endpoint e le regole L7 per le decisioni CONFIG:PROPOSED e /wait. Aggiungi copertura per una regola con due endpoint e verifica che entrambi i riassunti elenchino ogni endpoint e ogni autorizzazione L7, o indichino il numero quando troncati.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

state:accepted

User Story. As an operator shipping OpenShell's OCSF to a SIEM, I want each proposal's audit record to name every endpoint it asks for, so the trail matches what a reviewer approves.

Problem Statement. Two audit records summarise a proposal with summarize_chunk_for_audit: CONFIG:PROPOSED, and the /wait CONFIG:APPROVED|REJECTED. That function is at openshell-supervisor-network/src/policy_local.rs:695, and it reads rule.endpoints.first() and .first() of its L7 rules. A proposal for [ports.ubuntu.com:80, 169.254.169.254:80] is therefore audited as on ports.ubuntu.com:80 GET /ubuntu-ports/** by /usr/bin/perl, with no sign that a second endpoint exists.

The gateway's own approval audit does list every endpoint (endpoints=[…]), so the two streams disagree about the same chunk.

Impact. Anyone who reads the sandbox-side OCSF record, whether a SIEM or an auditor, sees only the benign endpoint. An agent can put the benign endpoint first.

Acceptance Criteria.

  • The PROPOSED and /wait decision summaries list every endpoint and every L7 allow, or say "N endpoints" when truncated.
  • There is a test with a two-endpoint rule.

Reproduction Steps.

  1. From a sandbox, POST http://policy.local/v1/proposals with one rule containing two endpoints.
  2. Compare openshell rule get <sandbox> (both endpoints listed) with the PROPOSED line in openshell logs <sandbox> --source sandbox (first only).

Environment.

  • openshell 0.1.2 (Homebrew)
  • Docker driver, Docker 29.4.1 linux/arm64 (Docker Desktop)
  • macOS 26.5.2
  • proposal_approval_mode = manual
  • Sources checked at main 0bca9fb

Logs. Only in source: the PROPOSED lines I observed each had a single endpoint. The first-only summary follows from policy_local.rs:699–706.

Lingua principale
Rust
Stelle
13.2k
Fork
1.6k
Merge medio
1g 20h
PR unite (30g)
348

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di NVIDIA/OpenShell

Tutte le issue di NVIDIA/OpenShell

Issue simili

Altre issue su Rust

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.